If you’re running Firefox 3.6, Mozilla strongly recommends you update to version 3.6.2. The new version corrects a critical security hole allowing an attacker to crash your browser and/or run arbitrary code on your machine.
The Security Warning advises:
Mozilla Foundation Security Advisory 2010-08
Title: WOFF heap corruption due to integer overflow
Impact: Critical
Announced: March 22, 2010
Reporter: Evgeny Legerov
Products: Firefox 3.6Fixed in: Firefox 3.6.2
DESCRIPTION
Security researcher Evgeny Legerov of Intevydis reported that the WOFF decoder contains an integer overflow in a font decompression routine. This flaw could result in too small a memory buffer being allocated to store a downloadable font. An attacker could use this vulnerability to crash a victim’s browser and execute arbitrary code on his/her system.
Note: Support for the WOFF downloadable font format is new in Firefox 3.6 (Gecko 1.9.2); this vulnerability does not affect products built on earlier versions of the Mozilla browser engine.
REFERENCES
Firefox recommends that all users upgrade to version 3.6.2 to correct this issue. The product can be downloaded from their website or by using the Check for Updates feature of the software.

Pingback: Firefox 3.6.2 Corrects Vulnerability | TEAM FORREST Blog
Pingback: Fred Posner
Pingback: mjgraves
Pingback: Firefox Security Vulnerability (Not an April Fool’s Joke) | VoIP Tech Chat